Show filters
109 Total Results
Displaying 51-60 of 109
Sort by:
Attacker Value
Unknown
CVE-2021-39313
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.
0
Attacker Value
Unknown
CVE-2021-38753
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
0
Attacker Value
Unknown
CVE-2020-14962
Disclosure Date: June 22, 2020 (last updated February 21, 2025)
Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.
0
Attacker Value
Unknown
CVE-2020-9003
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
0
Attacker Value
Unknown
CVE-2018-7717
Disclosure Date: March 05, 2018 (last updated November 26, 2024)
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
0
Attacker Value
Unknown
CVE-2017-16356
Disclosure Date: February 20, 2018 (last updated November 26, 2024)
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.
0
Attacker Value
Unknown
CVE-2017-14125
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2017-1002015
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
0
Attacker Value
Unknown
CVE-2017-1002012
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
0
Attacker Value
Unknown
CVE-2017-1002013
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
0